Firefox 浏览器附加组件
  • 扩展
  • 主题
    • 适用于 Firefox
    • 字典和语言包
    • 其他浏览器网站
    • 适用于 Android 的附加组件
登录
Canvas AuTOTP 预览

Canvas AuTOTP 作者: Perseus Lynx

Autofill 2FA codes for Canvas-based sites that support ADFS. Bypass MS Authenticator!

0 (0 reviews)0 (0 reviews)
2 个用户2 个用户
您需要 Firefox 来使用此扩展
下载 Firefox 并安装扩展
下载文件

扩展元数据

屏幕截图
No more annoying MS Authenticator!A screenshot of the UI
关于此扩展
Canvas AuTOTP

A browser extension that autofills 2FA TOTP codes for Canvas-based sites that support ADSF

Microsoft Authenticator bypass!!

Usage
[!warning]
This WILL reduce the security of your account.
You will be using the same device for something that is intended to use 2.
There is no secrets encryption as of v1.0 (for maximum convenience)

You must only complete this steps once per site

It takes 1-2 minutes.

(Important! Please follow)
  1. Install this extension in your browser
  2. Go to Security Info (microsoft.com)
  3. Click on Add Sign-in method -> Microsoft Authenticator
  4. Click on I want to use a different authenticator app -> Next
  5. Click on Can't scan image?
  6. Copy the contents after "Secret key: " by clicking the Copy button next to it -> Next
  7. On a new tab go to the login page for the site you wish to skip the MFA
  8. If you get automatically logged in, log out
  9. In that tab, open the "Canvas AuTOTP" extension by clicking on it
  10. Paste the secret that you copied from earlier -> click the Submit button -> click the Copy Code
  11. Go back to the microsoft.com tab and paste the code there
  12. Change "Default Sign-in method" by clicking on Change (above the sign-in methods but below the title)
  13. In the popup, click the downwards arrow and select App based authentication or hardware token - code
  14. Click Confirm

That's it! Once you login in on your canvas site, it should automatically fill in the code and sign you in.

How it works

At the core it just autofills TOTP (Time-based One Time PINs).

TOTP are generated from a secret, which must be initially provided by the login management server, in this case Microsoft. They are usually regenerated every 30 seconds. The TOTP generation functionality is borrowed from Turistu, for more information see Credit.

What I have made is just a wrapper for that TOTP generation code, and automated it's generation and completion for Canvas-based sites.

The program stores the secrets in the Extension Storage, and each secret is associated with a key of the domain that it works on.

When you are in a website that contains /adfs/ls/ in its url, the program interprets it as a Canvas login page and searches and tries to autocomplete the input to submit the TOTP. Once it does that, it automatically clicks the login button aswell.

Since I wanted this extension to be a superset of TOTP, it also includes the ability to manually copy the TOTP codes.

Credit

The TOTP functionality is the one from totp-in-javascript by turistu
评分 0(1 位用户)
登录以评价此扩展
目前尚无评分

已保存星级评分

5
0
4
0
3
0
2
0
1
0
尚无评价
权限与数据详细了解

必要权限:

  • 获取浏览器标签页
  • 访问您在所有网站的数据
更多信息
附加组件链接
  • 主页
  • 用户支持网站
  • 支持邮箱
版本
1.0
大小
138.5 KB
上次更新
6 个月前 (2025年2月9日)
相关分类
  • 隐私和安全
许可证
仅 GNU 通用公共许可证 v3.0
版本历史
  • 查看所有版本
标签
  • password manager
  • security
添加到收藏集
举报此附加组件
Perseus Lynx 制作的更多扩展
  • 目前尚无评分

  • 目前尚无评分

  • 目前尚无评分

  • 目前尚无评分

  • 目前尚无评分

  • 目前尚无评分

转至 Mozilla 主页

附加组件

  • 关于
  • Firefox 附加组件博客
  • 扩展工坊
  • 开发者中心
  • 开发者政策
  • 社区博客
  • 论坛
  • 报告缺陷
  • 评价指南

浏览器

  • Desktop
  • Mobile
  • Enterprise

产品

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • 隐私
  • Cookie
  • 法律

除非另有注明,否则本网站上的内容可按知识共享 署名-相同方式共享 3.0 或更新版本使用。